Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1of 8

1

Topic 9 – Controls related to the overall computer


environment (IT GENERAL CONTROLS)

Week: 20 – 24 May 2024


This session’s objective is to:
1. Define and explain general controls; and
2. understand, explain and apply the following five
categories of general controls in a practical scenario:
- Organisational controls and personnel practices
- System development and change controls
- Business continuity controls
- Operating controls
- Access controls

2
Sources:
- Auditing Fundamentals 2nd Edition: Chapter 5,
pages 152 – 169
- Graded Questions 3rd Edition: Chapter 5

3
5.8.1 Organisational controls and personnel practices
 Delegation of responsibility
- Steering committee
- CIO
- IT manager

 Segregation of duties
- Between development (technical staff), operations and security is key.

 Reporting, supervision and review


- Independent review of logs is extremely important.

 Personnel practices
- Issues to consider: Employing, leave, rotation of duties, training and
dismissals/resignations

Slide 4
3
5.8.2 Systems development and change controls
 SDLC
- Request submission, needs assessment and selection
- Planning and design
- Systems development and testing (5 types of testing)
- Implementation
- Post-implementation review

 Program change controls


- Process should be similar to the SDLC

Slide 5
4
5.8.3 Access controls
 Distinguish between physical and logical access
 Preventative
- Security policy
- Physical access
- Logical access (ID, Authentication and Authorisation)
 Detective and corrective
- Logs, registers and reports
 Other security controls
- Library
- Communication (Encryption, Firewalls, call-back, anti-virus and
independent certification)

Slide 6
5
5.8.4 Business continuity controls
 Risks can be physical or logical
 Preventative
- Security policy
- Physical access
- Logical access (ID, Authentication and Authorisation)

 Detective and corrective


- Back-ups and an emergency recovery plan
- Insurance

Slide 7
6
5.8.5 Operating controls and maintenance
 Technical in nature
- Scheduling
- Standards and policies
- Managing data, programs and documentation
- Logs
- Policies for users

Slide 8
7

You might also like